Latest CVE Feed
-
3.5
LOWCVE-2009-3210
Multiple cross-site scripting (XSS) vulnerabilities in the Print (aka Printer, e-mail and PDF versions) module 5.x before 5.x-4.8 and 6.x before 6.x-1.8, a module for Drupal, allow remote authenticated users to inject arbitrary web script or HTML via unsp... Read more
- Published: Sep. 16, 2009
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2009-4371
Cross-site scripting (XSS) vulnerability in the Locale module (modules/locale/locale.module) in Drupal Core 6.14, and possibly other versions including 6.15, allows remote authenticated users with "administer languages" permissions to inject arbitrary web... Read more
Affected Products : drupal- Published: Dec. 21, 2009
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2014-8893
Multiple cross-site scripting (XSS) vulnerabilities in (1) mainpage.jsp and (2) GetImageServlet.img in IBM TRIRIGA Application Platform 3.2.1.x, 3.3.2 before 3.3.2.3, and 3.4.1 before 3.4.1.1 allow remote authenticated users to inject arbitrary web script... Read more
Affected Products : tririga_application_platform- Published: Jan. 29, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2024-37234
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Kodezen Limited Academy LMS.This issue affects Academy LMS: from n/a through 2.0.4.... Read more
Affected Products :- Published: Jul. 06, 2024
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2012-0090
Unspecified vulnerability in the Oracle Imaging and Process Management component in Oracle Fusion Middleware 10.1.3.6.0 allows remote authenticated users to affect integrity via unknown vectors related to Web, a different vulnerability than CVE-2012-0092.... Read more
Affected Products : fusion_middleware- Published: Oct. 16, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2015-0130
Cross-site scripting (XSS) vulnerability in Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 4.x before 4.0.7 IF6 and 5.x before 5.0.2 IF5; Rational Quality Manager (RQM) 4.x before 4.0.7 IF6 and 5.x before 5.0.... Read more
- Published: Jul. 20, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-2670
Cross-site scripting (XSS) vulnerability in Properties.do in ZOHO ManageEngine OpStor before build 8500 allows remote authenticated users to inject arbitrary web script or HTML via the name parameter, a different vulnerability than CVE-2014-0344.... Read more
Affected Products : manageengine_opstor- Published: Mar. 29, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2013-5646
Cross-site scripting (XSS) vulnerability in Roundcube webmail 1.0-git allows remote authenticated users to inject arbitrary web script or HTML via the Name field of an addressbook group.... Read more
- Published: Aug. 29, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2024-6792
The WP ULike WordPress plugin before 4.7.2.1 does not properly sanitize user display names when rendering on a public page.... Read more
- Published: Sep. 06, 2024
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2024-57159
07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaWorkReport/add.html.... Read more
Affected Products : 07flycms- Published: Jan. 16, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Cross-Site Request Forgery
-
3.5
LOWCVE-2025-24429
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass allowing read only access. A low-privileged attacker could le... Read more
- Published: Feb. 11, 2025
- Modified: Apr. 16, 2025
- Vuln Type: Authorization
-
3.5
LOWCVE-2024-6446
An issue has been discovered in GitLab affecting all versions starting from 17.1 to 17.1.7, 17.2 prior to 17.2.5 and 17.3 prior to 17.3.2. A crafted URL could be used to trick a victim to trust an attacker controlled application.... Read more
Affected Products : gitlab- Published: Sep. 12, 2024
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2024-58248
nopCommerce before 4.80.0 does not offer locking for order placement. Thus there is a race condition with duplicate redeeming of gift cards.... Read more
Affected Products : nopcommerce- Published: Apr. 16, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Race Condition
-
3.5
LOWCVE-2025-26865
Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz. This issue affects Apache OFBiz: from 18.12.17 before 18.12.18. It's a regression between 18.12.17 and 18.12.18. In case you use something like that, ... Read more
Affected Products : ofbiz- Published: Mar. 10, 2025
- Modified: Jun. 23, 2025
-
3.5
LOWCVE-2013-6913
Cross-site scripting (XSS) vulnerability in a search component in Cybozu Garoon before 3.7.2, when Internet Explorer is used, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Dec. 05, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2015-4917
Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 allows remote authenticated users to affect integrity via unknown vectors related to Security, a different vulnerability than CVE-2015-4892.... Read more
Affected Products : supply_chain_products_suite- Published: Oct. 22, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-1040
Multiple cross-site scripting (XSS) vulnerabilities in the administrative backend in BEdita 3.4.0 allow remote authenticated users to inject arbitrary web script or HTML via the (1) lrealname field in the editProfile form to index.php/home/profile; the (2... Read more
Affected Products : bedita- Published: Jan. 15, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-8897
Cross-site scripting (XSS) vulnerability in the Collaboration Server in IBM InfoSphere Master Data Management Server for Product Information Management 9.x through 9.1 and InfoSphere Master Data Management - Collaborative Edition 10.x through 10.1, 11.0 b... Read more
- Published: Dec. 22, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-7386
Multiple cross-site scripting (XSS) vulnerabilities in includes/metaboxes.php in the Gallery - Photo Albums - Portfolio plugin 1.3.47 for WordPress allow remote authenticated users to inject arbitrary web script or HTML via the (1) Media Title or (2) Medi... Read more
Affected Products : gallery_-_photo_albums_-_portfolio- Published: Sep. 28, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2008-3097
Cross-site scripting (XSS) vulnerability in the Tinytax module (aka Tinytax taxonomy block) 5.x before 5.x-1.10-1 for Drupal allows remote authenticated users to inject arbitrary web script or HTML, probably by creating a crafted taxonomy term.... Read more
Affected Products : tinytax_taxonomy_block_module- Published: Jul. 09, 2008
- Modified: Apr. 09, 2025